From owner-freebsd-announce@FreeBSD.ORG Thu Mar 15 08:13:25 2007 Return-Path: X-Original-To: freebsd-announce@freebsd.org Delivered-To: freebsd-announce@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id EDFA316A401; Thu, 15 Mar 2007 08:13:24 +0000 (UTC) (envelope-from security-advisories@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [69.147.83.40]) by mx1.freebsd.org (Postfix) with ESMTP id DAAFB13C468; Thu, 15 Mar 2007 08:13:24 +0000 (UTC) (envelope-from security-advisories@freebsd.org) Received: from freefall.freebsd.org (cperciva@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id l2F8DOtI003436; Thu, 15 Mar 2007 08:13:24 GMT (envelope-from security-advisories@freebsd.org) Received: (from cperciva@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id l2F8DOcK003434; Thu, 15 Mar 2007 08:13:24 GMT (envelope-from security-advisories@freebsd.org) Date: Thu, 15 Mar 2007 08:13:24 GMT Message-Id: <200703150813.l2F8DOcK003434@freefall.freebsd.org> X-Authentication-Warning: freefall.freebsd.org: cperciva set sender to security-advisories@freebsd.org using -f From: FreeBSD Errata Notices To: FreeBSD Errata Notices Precedence: bulk Cc: Subject: [FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-07:05.freebsd-update X-BeenThere: freebsd-announce@freebsd.org X-Mailman-Version: 2.1.5 Reply-To: freebsd-stable@freebsd.org List-Id: "Project Announcements \[moderated\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 15 Mar 2007 08:13:25 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ============================================================================= FreeBSD-EN-07:05.freebsd-update Errata Notice The FreeBSD Project Topic: FreeBSD Update problems updating SMP kernels Category: core Module: usr.sbin Announced: 2007-03-15 Affects: FreeBSD 6.2 Corrected: 2007-03-08 05:43:12 UTC (RELENG_6, 6.2-STABLE) 2007-03-15 08:06:11 UTC (RELENG_6_2, 6.2-RELEASE-p3) For general information regarding FreeBSD Errata Notices and Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit . I. Background FreeBSD Update is a system for building, distributing, and installing binary security and errata updates to the FreeBSD base system. Starting with FreeBSD 6.2-RELEASE, the FreeBSD Update client software, freebsd-update(8), has been included in the FreeBSD base system. II. Problem Description Due to a programming error in the FreeBSD Update client, kernels built from the default SMP kernel configuration (including those distributed as part of the release) are not correctly identified as such. On the i386 platform, they are not recognized; on the amd64 platform, they are mis-identified as GENERIC kernels. III. Impact On the i386 platform, if a system is running a kernel built from the default SMP kernel configuration, and this kernel is installed somewhere other than /boot/SMP/kernel, the FreeBSD Update client will not download and install updates for it. On the amd64 platform, if a system is running a kernel built from the default SMP kernel configuration, and this kernel is installed somewhere other than /boot/SMP/kernel, the FreeBSD Update client will replace it with a kernel built from the GENERIC (single-processor) kernel configuration. IV. Workaround As described in Security Advisories and Errata Notices, it is possible to update FreeBSD systems by applying source code patches and rebuilding the affected components. Note that systems which are not running SMP kernels are not affected. Note also that this problem applies only to FreeBSD 6.2 systems using the FreeBSD Update client distributed as part of the FreeBSD base system. The FreeBSD Update client distributed as security/freebsd-update in the FreeBSD Ports Collection is not affected. V. Solution Perform one of the following: 1) Upgrade your affected system to 6-STABLE or to the RELENG_6_2 errata branch dated after the correction date. 2) To patch your present system: The following patch has been verified to apply to FreeBSD 6.2 systems. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch http://security.FreeBSD.org/patches/EN-07:05/freebsd-update.patch # fetch http://security.FreeBSD.org/patches/EN-07:05/freebsd-update.patch.asc b) Execute the following commands as root: # cd /usr/src # patch < /path/to/patch # cd /usr/src/usr.sbin/freebsd-update/ # make obj && make && make install V.1. IMPORTANT NOTES to users of FreeBSD Update: a) i386 systems: It is possible that past kernel updates have not been downloaded and installed by FreeBSD Update. To ensure that all available updates have been installed, run FreeBSD Update twice; first to download and install an updated FreeBSD Update client, and second to download and install any updates which were missed earlier. b) amd64 systems: It is possible that systems which were initially installed with an SMP kernel have been "updated" by replacing the kernel with a GENERIC kernel. To see which kernel is running, run # sysctl kern.smp.maxcpus which will report either 1 (GENERIC kernel) or 16 (SMP kernel). (Note that `uname -i`, the standard mechanism for determining a kernel ident, returns "GENERIC" on both amd64 GENERIC and SMP kernels.) If FreeBSD Update has replaced an SMP kernel by a GENERIC kernel, repeatedly run # freebsd-update rollback and reboot until the system is running an SMP kernel. Once you have verified that the system is running the correct kernel, run FreeBSD Update twice *without rebooting*. The first time FreeBSD Update is run it might replace an SMP kernel with a GENERIC kernel; but on the second run (after an updated FreeBSD Update client is installed, and as long as the system has not been rebooted into the wrong kernel) it will download the correct kernel. VI. Correction details The following list contains the revision numbers of each file that was corrected in FreeBSD. Branch Revision Path - ------------------------------------------------------------------------- RELENG_6 src/usr.sbin/freebsd-update/freebsd-update.sh 1.2.2.4 RELENG_6_2 src/UPDATING 1.416.2.29.2.5 src/sys/conf/newvers.sh 1.69.2.13.2.5 src/usr.sbin/freebsd-update/freebsd-update.sh 1.2.2.2.2.2 - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at http://security.FreeBSD.org/advisories/FreeBSD-EN-07:05.freebsd-update -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (FreeBSD) iD8DBQFF+P8FFdaIBMps37IRAqbPAJ4viqc2Sgon8Yorc9+SHN+NdEHHmgCfStee H4onavq1Yojf8V6t1HsEDxQ= =Ydbd -----END PGP SIGNATURE-----